7.2
CVE-2008-0008
- EPSS 0.05%
- Veröffentlicht 29.01.2008 00:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail via attacks such as resource exhaustion.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pulseaudio ≫ Pulseaudio Version0.9.6
Mandrakesoft ≫ Mandrake Linux Version2007.1
Mandrakesoft ≫ Mandrake Linux Version2007.1 Editionx86_64
Mandrakesoft ≫ Mandrake Linux Version2008.0
Mandrakesoft ≫ Mandrake Linux Version2008.0 Editionx86_64
Redhat ≫ Fedora Version7
Redhat ≫ Fedora Version8
Mandrakesoft ≫ Mandrake Linux Version2007.1 Editionx86_64
Mandrakesoft ≫ Mandrake Linux Version2008.0
Mandrakesoft ≫ Mandrake Linux Version2008.0 Editionx86_64
Redhat ≫ Fedora Version7
Redhat ≫ Fedora Version8
Pulseaudio ≫ Pulseaudio Version0.9.8
Mandrakesoft ≫ Mandrake Linux Version2007.1
Mandrakesoft ≫ Mandrake Linux Version2007.1 Editionx86_64
Mandrakesoft ≫ Mandrake Linux Version2008.0
Mandrakesoft ≫ Mandrake Linux Version2008.0 Editionx86_64
Redhat ≫ Fedora Version7
Redhat ≫ Fedora Version8
Mandrakesoft ≫ Mandrake Linux Version2007.1 Editionx86_64
Mandrakesoft ≫ Mandrake Linux Version2008.0
Mandrakesoft ≫ Mandrake Linux Version2008.0 Editionx86_64
Redhat ≫ Fedora Version7
Redhat ≫ Fedora Version8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.123 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.